PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance3 min readReviewed September 20266 sources

CERT-In AIBOM requirements: Table 10 minimum elements explained

CERT-In's Version 2.0 guidelines give India's clearest definition of an AIBOM and its minimum elements. This article sets out what the guidelines say and how to put the elements into a CycloneDX or SPDX document.

Key takeaways
  • CERT-In's guidelines, Version 2.0, are dated 9 July 2025 and cover SBOM, CBOM, QBOM, AIBOM and HBOM.
  • Section 9 defines the AIBOM and lists four benefits: security, transparency, compliance and risk management.
  • Table 10 lists minimum elements starting with model name, version, type, developer and licensing.
  • Each element maps to a field in CycloneDX ML-BOM or the SPDX 3.0 AI and Dataset profiles.

Where the requirements come from

CERT-In, India's national Computer Emergency Response Team, published Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, dated 9 July 2025 [1]. Section 9 covers the AIBOM. It defines it as "a comprehensive list of components used in building, training, and deploying AI models" and gives four benefits: security (identifying vulnerabilities in AI models), transparency (visibility into components, algorithms and data sources), compliance (demonstrating adherence to regulation and standards) and risk management (inventorying technological and data elements and their dependencies) [1].

Who it applies to

The guidelines are aimed at government, public-sector and essential-services organisations and at software exporters and service providers [1]. Reporting on the AIBOM section notes that organisations engaged in AI procurement are expected to include an AIBOM and to maintain AIBOMs for systems they use, procure and develop [2]. Legal commentary describes the framework as having broad applicability to regulated entities and organisations that develop, integrate or deploy AI systems [3].

Table 10: minimum elements

The following entries of Table 10 are as they appear in the guidelines [1]. The table includes further elements after Data Sets Information; consult the published PDF for the complete list and wording.

ElementCERT-In description (summary)CycloneDXSPDX 3.0
Model NameOfficial identifier for tracking and referencecomponent.namename
Model VersionVersion number documenting changescomponent.versionpackageVersion
Model TypeClassification such as text generation or image classificationmodelCard.modelParameters.tasktypeOfModel
Model DeveloperDeveloper or responsible organisationsupplier / manufacturersuppliedBy
Model Licensing InformationLicences for the model and its componentslicensesLicensing relationships
Software DependenciesLibraries, frameworks, operating system requirementsdependenciesdependsOn relationships
ML Models and AlgorithmsModels and algorithms used in decision processesmodelParameters.approach, architectureFamilytypeOfModel, informationAboutTraining
Model Performance MetricsAccuracy, precision, recall, F1 scorequantitativeAnalysis.performanceMetricsmetric
Data SourceOrigin of training data: proprietary, public, real-time or syntheticdata component with provenanceDatasetPackage, dataCollectionProcess
Data Sets InformationInformation about the datasets usedmodelParameters.datasetsDatasetPackage properties

The CycloneDX and SPDX columns are suggested mappings based on the CycloneDX 1.6 schema and the SPDX 3.0.1 AI and Dataset profiles [4][5][6]. They are not part of CERT-In's guidance.

Summaries by commentators also refer to elements such as intended and out-of-scope usage, security considerations and known vulnerabilities [3][2]. CycloneDX's considerations (use cases, technical limitations) and SPDX's limitation and safetyRiskAssessment provide places to record them.

Formats

CERT-In recognises SPDX and CycloneDX as SBOM formats [1], and both support AI content. See SPDX 3.0 AI vs CycloneDX ML-BOM.

Implementing the elements

  1. Choose a format and fix a field mapping like the one above.
  2. Generate AIBOMs for each AI system in scope (AIBOM generation).
  3. Write a validation policy requiring every Table 10 element (How to validate an AIBOM).
  4. Add the same requirement to supplier contracts.
  5. Regenerate and revalidate when models change.

How the AIBOM relates to the other BOMs in the guidelines

The same guidelines define 21 minimum SBOM fields, as well as CBOM, QBOM and HBOM elements [1]. The AIBOM's Software Dependencies element overlaps with the SBOM, so many organisations reference the serving stack's SBOM from the AIBOM rather than repeating it. Where a model runs on dedicated accelerators, the HBOM covers the hardware. Treating the five BOMs as linked records avoids duplicated effort and conflicting versions.

How IntelliXBOM helps

IntelliXBOM validates CycloneDX and SPDX AIBOMs against a CERT-In AIBOM field policy, reports missing elements per model, and keeps version history so gaps and fixes are visible over time. It maps the result to CERT-In and other frameworks as timestamped evidence.

This article summarises public guidance and is not legal advice.

Frequently asked questions

What are CERT-In's AIBOM minimum elements?

Table 10 of CERT-In's Version 2.0 guidelines begins with Model Name, Model Version, Model Type, Model Developer, Model Licensing Information, Software Dependencies, ML Models and Algorithms, Model Performance Metrics, Data Source and Data Sets Information. Refer to the published PDF for the full table.

Which formats does CERT-In accept for BOMs?

The guidelines name SPDX and CycloneDX. Both have AI-specific structures: CycloneDX ML-BOM with model cards, and SPDX 3.0 AI and Dataset profiles.

Are CERT-In AIBOM requirements mandatory?

The document is a set of technical guidelines aimed at government, public-sector and essential-services organisations and software exporters. Whether it binds a particular organisation depends on contracts, sector rules and procurement conditions, so seek advice for your situation.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. How Do CERT-In's AIBOM Guidelines Affect AI Procurement?MediaNamawww.medianama.com/2025/07/223-cert-in-ai-bill-of-materials-guidelines/
  3. CERT-In's New BOM Guidelines: What India's Software, AI, and Hardware Ecosystem Needs to KnowAZB & Partnerswww.azbpartners.com/bank/cert-ins-new-bom-guidelines-what-indias-software-ai-and-hardware-ecosystem-needs-to-know/
  4. CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
  5. SPDX 3.0.1 specification: AI profile, AIPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/AI/Classes/AIPackage/
  6. SPDX 3.0.1 specification: Dataset profile, DatasetPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/Dataset/Classes/DatasetPackage/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.